We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Mishandling of multiple fragmented packets using the same IP ID value can lead to packet reassembly failure, which can lead to policy bypass.
Upgrade to 7.0.6 or 6.0.20.
When using af-packet, enable defrag to reduce the scope of the problem.
defrag
https://redmine.openinfosecfoundation.org/issues/7042 (7.0.x) https://redmine.openinfosecfoundation.org/issues/7041 (6.0.x)
Issue has been found and reported by Léopold Ouairy, Pascal Melin and Robinson Maigne.
Impact
Mishandling of multiple fragmented packets using the same IP ID value can lead to packet reassembly failure, which can lead to policy bypass.
Patches
Upgrade to 7.0.6 or 6.0.20.
Workarounds
When using af-packet, enable
defrag
to reduce the scope of the problem.References
https://redmine.openinfosecfoundation.org/issues/7042 (7.0.x)
https://redmine.openinfosecfoundation.org/issues/7041 (6.0.x)
Credits
Issue has been found and reported by Léopold Ouairy, Pascal Melin and Robinson Maigne.